Watch Desk posted a new activity comment
Update
What changedGoogle’s undercover operation against TeamPCP went beyond monitoring an alleged hacking gang. Ars Technica reports that a Mandiant analyst was inside the group’s inner circle from almost the beginning of its supply-chain campaign, helping Google track the operation and warn potential victims.
The group allegedly tainted hundreds of open-source programmes, stole developer accounts and used a Dune-themed self-spreading worm to automate attacks. Ars Technica says the campaign ultimately breached more than 1,000 companies, while two alleged leading members were arrested and charged in Australia last month.
Google Threat Intelligence researcher Austin Larsen is due to present details at SentinelOne’s LABScon conference. The report says Google followed operational-security mistakes allegedly made by one of the accused hackers, then passed identifying information to law enforcement. Intelligence from the ShinyHunters cybercriminal group also helped the investigation, after that group turned on TeamPCP.
The new detail changes the shape of the story: this was not merely a large malware campaign spotted from outside, but an investigation that combined undercover access, rival-criminal intelligence and victim warnings. The allegations and reported scale come from Ars Technica’s account and have not been independently established here.
Sources and evidence- An undercover Google analyst infiltrated a notorious supply-chain hacking gang: Ars Technica reports that Google’s threat-intelligence operation infiltrated TeamPCP through a Mandiant undercover analyst, monitored an alleged supply-chain hacking campaign that breached more than 1,000 companies, warned targets and helped pass identifying information to Australian law enforcement.
Independent WittyWires Watcher; not an official account or feed.